VLDB 2026 Research / reviewers in the wild / expert
Daniel Timko
dblp:336/7284
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2024
0009-0002-3964-1342ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Smishing Dataset I: Phishing SMS Dataset from Smishtank.comabstractWhile smishing (SMS Phishing) attacks have risen to become one of the most common types of social engineering attacks, there is a lack of relevant smishing datasets. One of the biggest challenges in the domain of smishing prevention is the availability of fresh smishing datasets. Additionally, as time persists, smishing campaigns are shut down and the crucial information related to the attack are lost. With the changing nature of smishing attacks, a consistent flow of new smishing examples is needed by both researchers and engineers to create effective defenses. In this paper, we present the community-sourced smishing datasets from the smishtank.com. It provides a wealth of information relevant to combating smishing attacks through the breakdown and analysis of smishing samples at the point of submission. In the contribution of our work, we provide a corpus of 1062 smishing samples that have been publicly submitted through the site. Each message includes information relating to the sender, message body, and any brands referenced in the message. Additionally, when a URL is found, we provide additional information on the domain, VirusTotal results, and a characterization of the URL. Through the open access of fresh smishing data, we empower academia and industries to create robust defenses against this evolving threat. Daniel Timko, Muhammad Lutfor Rahman |
CODASPY | 1 |
| 2023 | A low-cost IoT-based Smart Farming System For Crop Recommendation and Resource ManagementabstractAgriculture not only plays a significant role in a nation’s economic development but is also the key to the survival of all life forms on this planet. Crop production has been immensely affected by global warming and the drastic changes in overall climate and rainfall patterns. Farmers who used to manually choose which crop to grow in a specific region given the soil, water, and atmospheric conditions can no longer do so owing to this change. Emerging technologies can be used to improve crop productivity by switching from traditional farming practices to relying on Machine Learning algorithms to monitor the soil and water quality along with the atmospheric conditions and to recommend the crops suitable to be grown based on these monitored factors. Having Internet of Things (IoT) work alongside Artificial Intelligence in our “Smart Farming System” has resulted in a powerful tool that will help farmers choose the right crop to grow. The soil parameters like soil nitrogen, soil phosphorus, soil potassium, soil moisture, and soil pH are gathered from the sensors using IoT. Similarly, atmospheric temperature is collected from another sensor using IoT. These values are fed into a chosen Machine Learning model, which performs the crop prediction. This prediction result is then sent to the mobile application, which acts as the User Interface (UI). This mobile application recommends suitable crops to farmers based on the parameter values collected from their fields and displayed on the application. Daniel Timko, Adityan Elangovan, Aruna Elangovan, Mike Sharko, Ali Ahmadinia |
IEEE Big Data | 1 |
| 2023 | Are Current CCPA Compliant Banners Conveying User's Desired Opt-Out Decisions? An Empirical Study of Cookie Consent Banners
Torsha Mazumdar, Daniel Timko, Muhammad Lutfor Rahman |
CANS | 2 |
| 2023 | Users Really Do Respond To SmishingabstractText phish messages, referred to as Smishing (SMS + phishing) is a type of social engineering attack where fake text messages are created, and used to lure users into responding to those messages. These messages aim to obtain user credentials, install malware on the phones, or launch smishing attacks. They ask users to reply to their message, click on a URL that redirects them to a phishing website, or call the provided number. Drawing inspiration by the works of Tu et al. on Robocalls and Tischer et al. on USB drives, this paper investigates why smishing works. Accordingly, we designed smishing experiments and sent phishing SMSes to 265 users to measure the efficacy of smishing attacks. We sent eight fake text messages to participants and recorded their CLICK, REPLY, and CALL responses along with their feedback in a post-test survey. Our results reveal that 16.92% of our participants had potentially fallen for our smishing attack. To test repeat phishing, we subjected a set of randomly selected participants to a second round of smishing attacks with a different message than the one they received in the first round. As a result, we observed that 12.82% potentially fell for the attack again. Using logistic regression, we observed that a combination of user REPLY and CLICK actions increased the odds that a user would respond to our smishing message when compared to CLICK. Additionally, we found a similar statistically significant increase when comparing Facebook and Walmart entity scenario to our IRS baseline. Based on our results, we pinpoint essentially message attributes and demographic features that contribute to a statistically significant change in the response rates to smishing attacks. Muhammad Lutfor Rahman, Daniel Timko, Hamid Wali, Ajaya Neupane |
CODASPY | 2 |
| 2023 | Saudi Arabian Perspective of Security, Privacy, and Attitude of Using Facial Recognition TechnologyabstractFacial Recognition Technology (FRT) is a pioneering field of mass surveillance that sparks privacy concerns and is considered a growing threat in the modern world. FRT has been widely adopted in the Kingdom of Saudi Arabia to improve public services and surveillance. Accordingly, the following study aims to understand the privacy and security concerns, trust, and acceptance of FRT in Saudi Arabia. Validated Privacy Concerns (IUIPC-8), Security Attitudes (SA-6), and Security Behavior (SeBIS) scales are used along with replicate studies from Pew Research Center trust questions and government trust questions. In addition, we examine potential differences between Saudis and Americans. To gain insights into these concerns, we conducted an online survey involving 53 Saudi Arabia citizens who are residing in the USA. We have collected data in the US instead of Saudi Arabia to avoid the regulatory challenges of the Saudi Data & Artificial Intelligence Authority (SDAIA). Responses from closed-ended questions revealed that Saudis score much lower than Americans when it comes to security attitudes, whereas they score lower when it comes to privacy concerns. We found no significant difference between Saudis’ and Americans’ acceptance of the use of FRT in different scenarios, but we found that Saudis trust advertisers more than Americans. Additionally, Saudis are more likely than Americans to agree that the government should strictly limit the use of FRT. Amani Mohammed Alqarni, Daniel Timko, Muhammad Lutfor Rahman |
PST | 2 |
| 2023 | Commercial Anti-Smishing Tools and Their Comparative Effectiveness Against Modern ThreatsabstractSmishing, also known as SMS phishing, is a type of fraudulent communication in which an attacker disguises SMS communications to deceive a target into providing their sensitive data. Smishing attacks use a variety of tactics; however, they have a similar goal of stealing money or personally identifying information (PII) from a victim. In response to these attacks, a wide variety of anti-smishing tools have been developed to block or filter these communications. Despite this, the number of phishing attacks continue to rise. In this paper, we developed a test bed for measuring the effectiveness of popular anti-smishing tools against fresh smishing attacks. To collect fresh smishing data, we introduce Smishtank.com, a collaborative online resource for reporting and collecting smishing data sets. The SMS messages were validated by a security expert and an in-depth qualitative analysis was performed on the collected messages to provide further insights. To compare tool effectiveness, we experimented with 20 smishing and benign messages across 3 key segments of the SMS messaging delivery ecosystem. Our results revealed significant room for improvement in all 3 areas against our smishing set. Most anti-phishing apps and bulk messaging services didn't filter smishing messages beyond the carrier blocking. The 2 apps that blocked the most smish also blocked 85-100% of benign messages. Finally, while carriers did not block any benign messages, they were only able to reach a 25-35% blocking rate for smishing messages. Our work provides insights into the performance of anti-smishing tools and the roles they play in the message blocking process. This paper would enable the research community and industry to be better informed on the current state of anti-smishing technology on the SMS platform. Daniel Timko, Muhammad Lutfor Rahman |
WISEC | 1 |